Remote VASP serving residents in Slovenia
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Slovenia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with Office for Money Laundering Prevention (UPPD) under ZPPDFT-2 before commencing operations
- Implementation of robust internal AML/CFT policies, procedures and controls
- Risk assessment frameworks covering customer, product and geographical risks
- Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) measures
- Record-keeping of transactions and customer data
- Reporting of suspicious transactions to UPPD
- Appointment of an AML officer
- Training for relevant employees
- Fit and proper assessment for management and beneficial owners
- If processing fiat payments for crypto transactions, may require a Payment Institution (PI) or Electronic Money Institution (EMI) license from Bank of Slovenia under PSD2 transposition (ZPlaS-1)
Key Restrictions
- Cross-border (non-local) operation without registration is not permitted — remote VASP must register with FURS (under ZPPML-1) and UPPD (under ZPPDFT-2)
- Local entity likely required: CASPs under MiCA must be legal persons established in the EU; current regime implies registration requires a Slovenian/EU nexus
- Under MiCA (future regime), a full CASP license from the national competent authority (likely ATVP or Bank of Slovenia) will replace the current AML registration
- If processing fiat payments, may need separate PI/EMI licensing from Bank of Slovenia
- No current statutory requirement for asset segregation, cold storage, or professional indemnity insurance (Pre-MiCA), but best practice expected
Key Risks
- Enforcement risk for unregistered remote operators: FURS/UPPD can issue warnings and impose AML/CFT sanctions; unregistered operation is illegal
- Regulatory ambiguity around whether a foreign-incorporated entity with no local office can register under current ZPPML-1/ZPPDFT-2 — the regime appears designed for locally established entities
- Transition risk: MiCA will introduce stricter licensing requirements (capital, governance, insurance) that may require restructuring
- UPPD enforcement details are not publicly named, increasing uncertainty about actual enforcement intensity against foreign VASPs
- If accepting fiat (EUR) payments, may inadvertently trigger PSD2 licensing requirements from Bank of Slovenia
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Act on the Prevention of Money Laundering and Terrorist Financing (ZPPML-1):
Competent Authority: The Financial Administration of the Republic of Slovenia (FURS) (Finančna uprava Republike Slovenije) is the primary supervisory authority for AML/CTF compliance, including the registration and supervision of VASPs.
Current Regime (ZPPML-1): Registration. Slovenia currently requires VASPs to register with FURS before they can operate. This is a registration for AML/CTF purposes, focusing on preventing illicit financial activities, rather than a full operational license that would typically cover aspects like prudential requirements, consumer protection, or market integrity comprehensively.
Requirement: Registration with FURS under ZPPML-1.
Future Regime (MiCA): Licensing. The EU's Markets in Crypto-Assets (MiCA) Regulation (Regulation (EU) 2023/1114) will introduce a comprehensive, harmonized licensing framework for crypto-asset service providers (CASPs) across all EU member states. MiCA will come into full effect for most crypto-assets by December 30, 2024 (stablecoin rules apply from June 30, 2024). Once MiCA is fully implemented, it will largely supersede the national AML-driven registration requirements for the activities it covers, introducing a full licensing regime with passporting rights across the EU.
If processing fiat payments for crypto transactions (e.g., enabling users to deposit/withdraw EUR to/from an exchange account):
Depending on the exact business model (e.g., holding client funds, initiating payments), such entities might fall under the scope of the Payment Services Act (Zakon o plačilnih storitvah in sistemih – ZPlaS-1), which transposes PSD2.
VASP Registration: Entities providing services of safeguarding private cryptographic keys on behalf of clients, or holding, storing, and transferring virtual currencies, are classified as "virtual asset service providers" (VASPs) under ZPPDFT-2.
Obligation to Register: VASPs must register with the Office for Money Laundering Prevention (UPPD). This is a registration requirement, not a full prudential licensing regime akin to banks or investment firms, but it entails strict AML/CFT compliance obligations.
Implementation of robust internal AML/CFT policies, procedures, and controls.
Risk assessment frameworks (customer, product, geographical risks).
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) measures.
Record-keeping of transactions and customer data.
Reporting of suspicious transactions to UPPD.
Appointment of an AML officer.
Training for relevant employees.
Fit and proper assessment for management and beneficial owners (though not as extensive as for licensed financial institutions).
Authorization: CASPs offering custody services will require authorization from a national competent authority (e.g., ATVP in Slovenia). This is a much more stringent licensing process than the current AML registration.
Legal form: CASPs must be legal persons established in the EU.
Issuing warnings and guidance: Educating the public about risks and informing businesses about compliance requirements, especially in anticipation of EU-wide regulations like MiCA (Markets in Crypto-Assets).
Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) supervision: The Office for Money Laundering Prevention (UPPD - Urad RS za preprečevanje pranja denarja) is the primary authority here. While they conduct supervision and impose measures, details of individual enforcement actions against specific companies (with fine amounts and outcomes) are not usually made public in the same way as in some other jurisdictions.
AML/CFT Supervisory Activities (General):
Entity Targeted: Virtual Asset Service Providers (VASPs) operating in Slovenia. Violation Type: Non-compliance with AML/CFT obligations (e.g., inadequate customer due diligence, suspicious transaction reporting failures, internal control deficiencies). Penalty Amount: Details are not typically made public for individual administrative measures, but can range from warnings to fines.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Slovenian residents must register with FURS (under ZPPML-1) and UPPD (under ZPPDFT-2) for AML/CFT purposes, and the current regime likely requires a local/EU nexus; operating unregistered from abroad carries enforcement risk, and the upcoming MiCA framework will impose a full CASP licensing requirement.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?